LPE and RCE in OpenSMTPD (CVE-2020-7247).
We discovered a vulnerability in OpenSMTPD, OpenBSD's mail server. This vulnerability is exploitable since May 2018 (commit a8e222352f, "switch smtpd to new grammar") and allows an attacker to execute arbitrary shell commands, as root.
https://www.openwall.com/lists/oss-security/2020/01/28/3
#opensmtpd #mail
Post #114
948